Vulnerability record · CVE-2019-1821 · published 16 May 2019
CVE-2019-1821: Cisco Prime Infrastructure and EPN Manager input validation RCE
Cisco · Evolved Programmable Network Manager
Cisco Prime Infrastructure and Evolved Programmable Network Manager fail to properly validate user-supplied input in the web-based management interface, allowing a malicious file upload to trigger code execution. The flaw is rated critical (CVSS 3.0 9.8) and affects administrative management software that typically holds broad network visibility and credentials.
Description
A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, remote attacker to execute code with root-level privileges on the underlying operating system. This vulnerability exist because the software improperly validates user-supplied input. An attacker could exploit this vulnerability by uploading a malicious file to the administrative web interface. A successful exploit could allow the attacker to execute code with root-level privileges on the underlying operating system.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with root-level remote code execution on network management infrastructure and a very high EPSS score make this a top remediation priority despite no KEV listing.
What it is
Cisco Prime Infrastructure and Evolved Programmable Network Manager fail to properly validate user-supplied input in the web-based management interface, allowing a malicious file upload to trigger code execution. The flaw is rated critical (CVSS 3.0 9.8) and affects administrative management software that typically holds broad network visibility and credentials.
Impact
An attacker who can reach the interface gains root-level code execution on the underlying operating system, giving full control of the management host and any data or credentials it holds.
Attack surface
Reached remotely over the network through the web-based management interface via a crafted file upload. The description states the attacker must be authenticated, though the CVSS vector lists PR:N, so the record is internally inconsistent on whether credentials are required; no user interaction is indicated.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.98051, 99.9th percentile), indicating elevated likelihood of exploitation activity. Reference tags are limited to vendor and third-party advisories, with no public exploit tag.
What to do
- Apply the Cisco security advisory cisco-sa-20190515-pi-rce updates for Prime Infrastructure and EPN Manager.
- Restrict network access to the management web interface to trusted administrative networks only.
- Enforce strong authentication and least privilege on administrative accounts, and audit who can upload files.
- Monitor and alert on unexpected file uploads or process creation on management hosts.
- If patching is delayed, isolate affected management appliances from general network segments.
Detection
- Review web server and application logs for file upload requests to administrative endpoints, especially unusual filenames or archive content.
- Hunt for unexpected child processes spawned by the web/application service, particularly shell or root-level execution.
- Monitor for new or modified files in web-accessible directories and for outbound connections from management hosts.
- Correlate authentication events with subsequent upload activity on Prime Infrastructure and EPN Manager systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-1821 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1821), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.